Stack-Based Buffer Overflow in TRENDnet TEW-432BRP Router
CVE-2026-10121

8.7HIGH

Key Information:

Vendor

Trendnet

Vendor
CVE Published:
30 May 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-10121?

A flaw has been discovered in the TRENDnet TEW-432BRP router, specifically within the formSetUrlFilter function located in the /goform/formSetUrlFilter file. This vulnerability arises from improper handling of the 'keyword_list' argument, which can lead to a stack-based buffer overflow. The exploitation of this vulnerability can be performed remotely, posing a significant risk to users. However, it is important to note that this product has been end-of-life (EOL) for over 15 years, with the vendor stating that they can no longer address or fix any vulnerabilities due to the lack of support for the device.

Affected Version(s)

TEW-432BRP 3.10B20

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

pjqwudi_Buoy (VulDB User)
VulDB CNA Team
.